|
Log-Analyse und Auswertung: pc sauber nach flacor.dat?Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
08.08.2010, 19:19 | #16 |
/// Selecta Jahrusso | pc sauber nach flacor.dat? Starte bitte OTL.exe und klicke auf den Quick Scan Button.
__________________ mfg, Daniel ASAP & UNITE Member Alliance of Security Analysis Professionals Unified Network of Instructors and Trusted Eliminators Lerne, zurück zu schlagen und unterstütze uns! TB Akademie |
10.08.2010, 19:05 | #17 |
| pc sauber nach flacor.dat? OTL.txt
__________________OTL Logfile: Code:
ATTFilter OTL logfile created on: 10.08.2010 19:55:53 - Run 2 OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\***\Desktop Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18882) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 51,00% Memory free 4,00 Gb Paging File | 3,00 Gb Available in Paging File | 70,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 303,35 Gb Total Space | 84,69 Gb Free Space | 27,92% Space Free | Partition Type: NTFS Drive D: | 150,69 Gb Total Space | 142,59 Gb Free Space | 94,62% Space Free | Partition Type: NTFS E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: BUERO Current User Name: *** Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Company Name Whitelist: On Skip Microsoft Files: On File Age = 90 Days Output = Standard Quick Scan ========== Processes (SafeList) ========== PRC - [2010.08.07 17:37:49 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Users\***\Desktop\OTL.exe PRC - [2009.10.01 12:58:26 | 000,238,952 | ---- | M] (Teruten) -- C:\Windows\System32\FsUsbExService.Exe PRC - [2009.09.05 18:29:06 | 000,385,024 | ---- | M] (shbox.de) -- C:\Program Files\FreePDF_XP\fpassist.exe PRC - [2009.07.21 15:34:28 | 000,185,089 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe PRC - [2009.07.20 12:30:50 | 000,813,584 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Logitech\SetPoint\SetPoint.exe PRC - [2009.07.10 12:42:32 | 000,055,824 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE PRC - [2009.05.27 03:27:04 | 029,262,680 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe PRC - [2009.05.13 17:48:18 | 000,108,289 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe PRC - [2009.04.10 23:27:38 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2009.03.02 14:08:43 | 000,209,153 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe PRC - [2008.11.24 23:31:12 | 000,087,904 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe PRC - [2008.11.24 23:31:08 | 000,239,968 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe PRC - [2008.01.18 23:38:40 | 001,008,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe PRC - [2007.06.15 13:57:42 | 000,145,504 | ---- | M] (B.H.A Corporation) -- C:\Windows\System32\bgsvcgen.exe PRC - [2007.05.17 19:00:38 | 000,699,104 | ---- | M] () -- C:\Program Files\NETGEAR\PS121v2\PS121v2.exe PRC - [2006.12.08 10:52:04 | 000,204,800 | ---- | M] (Fujitsu Siemens Computers) -- C:\FirstSteps\OnlineDiagnostic\TestManager\TestHandler.exe PRC - [2006.09.28 11:20:00 | 000,049,152 | ---- | M] (Ulead Systems, Inc.) -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe PRC - [2006.05.24 08:49:14 | 000,024,576 | ---- | M] (Syntek America Inc.) -- C:\Windows\System32\StkASv2K.exe PRC - [2005.06.10 04:44:02 | 000,081,920 | R--- | M] (InstallShield Software Corporation) -- C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe ========== Modules (SafeList) ========== MOD - [2010.08.07 17:37:49 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Users\***\Desktop\OTL.exe MOD - [2009.04.10 23:21:40 | 001,686,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll MOD - [2008.01.18 23:33:02 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msscript.ocx ========== Win32 Services (SafeList) ========== SRV - [2010.03.29 08:51:54 | 000,068,000 | ---- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- C:\Program Files\NOS\bin\getPlus_Helper.dll -- (getPlusHelper) getPlus(R) SRV - [2009.12.16 19:26:00 | 003,453,712 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\Windows\System32\GameMon.des -- (npggsvc) SRV - [2009.10.01 12:58:26 | 000,238,952 | ---- | M] (Teruten) [Auto | Running] -- C:\Windows\System32\FsUsbExService.Exe -- (FsUsbExService) SRV - [2009.07.21 15:34:28 | 000,185,089 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2009.07.20 12:28:10 | 000,121,360 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe -- (LBTServ) SRV - [2009.05.27 03:27:04 | 029,262,680 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe -- (MSSQL$SQLEXPRESS) SQL Server (SQLEXPRESS) SRV - [2009.05.13 17:48:18 | 000,108,289 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2008.11.24 23:31:12 | 000,087,904 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe -- (SQLWriter) SRV - [2008.11.24 23:31:08 | 000,239,968 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe -- (SQLBrowser) SRV - [2008.11.24 23:31:08 | 000,045,408 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe -- (MSSQLServerADHelper) SRV - [2008.01.18 23:38:26 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend) SRV - [2008.01.18 23:34:44 | 000,035,328 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\lpdsvc.dll -- (LPDSVC) SRV - [2007.06.15 13:57:42 | 000,145,504 | ---- | M] (B.H.A Corporation) [Auto | Running] -- C:\Windows\System32\bgsvcgen.exe -- (bgsvcgen) SRV - [2006.12.14 17:00:00 | 000,544,768 | ---- | M] (Magix AG) [On_Demand | Stopped] -- C:\Program Files\Common Files\MAGIX Shared\UPnPService\UPnPService.exe -- (UPnPService) SRV - [2006.12.08 10:52:04 | 000,204,800 | ---- | M] (Fujitsu Siemens Computers) [Auto | Running] -- C:\FirstSteps\OnlineDiagnostic\TestManager\TestHandler.exe -- (TestHandler) SRV - [2006.09.28 11:20:00 | 000,049,152 | ---- | M] (Ulead Systems, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe -- (UleadBurningHelper) SRV - [2006.05.24 08:49:14 | 000,024,576 | ---- | M] (Syntek America Inc.) [Auto | Running] -- C:\Windows\System32\StkASv2K.exe -- (StkASSrv) SRV - [2005.11.17 15:18:52 | 001,527,900 | ---- | M] (MAGIX®) [On_Demand | Stopped] -- C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe -- (FirebirdServerMAGIXInstance) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\XDva356.sys -- (XDva356) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\XDva352.sys -- (XDva352) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\pfc.sys -- (pfc) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\pccsmcfd.sys -- (pccsmcfd) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\ipinip.sys -- (IpInIp) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RTKVHDA.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\EagleNT.sys -- (EagleNT) DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\blbdrive.sys -- (blbdrive) DRV - [2010.04.03 22:55:32 | 011,573,800 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm) DRV - [2010.03.13 14:08:30 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\sptd.sys -- (sptd) DRV - [2009.12.20 10:53:32 | 000,234,016 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169) DRV - [2009.12.15 20:37:25 | 000,005,632 | ---- | M] () [File_System | System | Running] -- C:\Windows\System32\drivers\StarOpen.sys -- (StarOpen) DRV - [2009.12.07 18:23:28 | 000,056,816 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt) DRV - [2009.09.21 10:33:06 | 000,036,608 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\FsUsbExDisk.Sys -- (FsUsbExDisk) DRV - [2009.08.04 21:43:38 | 000,278,728 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\atksgt.sys -- (atksgt) DRV - [2009.08.04 21:43:37 | 000,025,416 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\lirsgt.sys -- (lirsgt) DRV - [2009.06.17 18:56:24 | 000,079,248 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LMouKE.Sys -- (LMouKE) DRV - [2009.06.17 18:56:16 | 000,037,392 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LMouFilt.Sys -- (LMouFilt) DRV - [2009.06.17 18:56:06 | 000,035,472 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LHidFilt.Sys -- (LHidFilt) DRV - [2009.06.17 18:55:26 | 000,063,248 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\L8042mou.Sys -- (L8042mou) DRV - [2009.06.17 18:55:18 | 000,020,240 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\L8042Kbd.sys -- (L8042Kbd) DRV - [2009.05.11 11:12:20 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv) DRV - [2009.04.10 21:45:26 | 000,113,664 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rmcast.sys -- (RMCAST) RMCAST (Pgm) DRV - [2009.04.10 21:42:56 | 000,073,216 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\USBAUDIO.sys -- (usbaudio) USB-Audiotreiber (WDM) DRV - [2009.03.30 11:33:03 | 000,096,104 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb) DRV - [2009.02.13 13:35:01 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys -- (avgio) DRV - [2007.07.12 16:35:02 | 000,305,176 | ---- | M] (Intel Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iastor.sys -- (iaStor) DRV - [2007.07.02 17:37:10 | 000,131,616 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvrd32.sys -- (nvrd32) DRV - [2007.07.02 17:37:08 | 000,110,112 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvstor32.sys -- (nvstor32) DRV - [2007.06.13 23:47:12 | 000,048,256 | ---- | M] (JMicron Technology Corp.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\jraid.sys -- (JRAID) DRV - [2007.03.08 17:47:42 | 000,013,824 | ---- | M] (SerComm) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NETGEARUHOST.sys -- (NETGEARUHOST) DRV - [2006.11.28 05:46:24 | 000,028,224 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\PCAMp50.sys -- (PCAMp50) DRV - [2006.11.28 05:46:22 | 000,027,072 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\PCASp50.sys -- (PCASp50) DRV - [2006.11.02 11:51:45 | 000,900,712 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ql2300.sys -- (ql2300) DRV - [2006.11.02 11:51:38 | 000,420,968 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adp94xx.sys -- (adp94xx) DRV - [2006.11.02 11:51:34 | 000,316,520 | ---- | M] (Emulex) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\elxstor.sys -- (elxstor) DRV - [2006.11.02 11:51:32 | 000,297,576 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpahci.sys -- (adpahci) DRV - [2006.11.02 11:51:25 | 000,235,112 | ---- | M] (ULi Electronics Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\uliahci.sys -- (uliahci) DRV - [2006.11.02 11:51:25 | 000,232,040 | ---- | M] (Intel Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iastorv.sys -- (iaStorV) DRV - [2006.11.02 11:51:00 | 000,147,048 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpu320.sys -- (adpu320) DRV - [2006.11.02 11:50:45 | 000,115,816 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ulsata2.sys -- (ulsata2) DRV - [2006.11.02 11:50:41 | 000,112,232 | ---- | M] (VIA Technologies Inc.,Ltd) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\vsmraid.sys -- (vsmraid) DRV - [2006.11.02 11:50:35 | 000,106,088 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ql40xx.sys -- (ql40xx) DRV - [2006.11.02 11:50:35 | 000,098,408 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ulsata.sys -- (UlSata) DRV - [2006.11.02 11:50:35 | 000,098,408 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpu160m.sys -- (adpu160m) DRV - [2006.11.02 11:50:24 | 000,088,680 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\nvraid.sys -- (nvraid) DRV - [2006.11.02 11:50:19 | 000,045,160 | ---- | M] (IBM Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nfrd960.sys -- (nfrd960) DRV - [2006.11.02 11:50:17 | 000,041,576 | ---- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iirsp.sys -- (iirsp) DRV - [2006.11.02 11:50:16 | 000,071,784 | ---- | M] (Silicon Integrated Systems) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sisraid4.sys -- (SiSRaid4) DRV - [2006.11.02 11:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvstor.sys -- (nvstor) DRV - [2006.11.02 11:50:11 | 000,071,272 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\djsvs.sys -- (aic78xx) DRV - [2006.11.02 11:50:10 | 000,067,688 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\arcsas.sys -- (arcsas) DRV - [2006.11.02 11:50:10 | 000,065,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_scsi.sys -- (LSI_SCSI) DRV - [2006.11.02 11:50:10 | 000,038,504 | ---- | M] (Silicon Integrated Systems Corp.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sisraid2.sys -- (SiSRaid2) DRV - [2006.11.02 11:50:10 | 000,037,480 | ---- | M] (Hewlett-Packard Company) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\hpcisss.sys -- (HpCISSs) DRV - [2006.11.02 11:50:09 | 000,067,688 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\arc.sys -- (arc) DRV - [2006.11.02 11:50:09 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iteraid.sys -- (iteraid) DRV - [2006.11.02 11:50:07 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iteatapi.sys -- (iteatapi) DRV - [2006.11.02 11:50:05 | 000,065,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_sas.sys -- (LSI_SAS) DRV - [2006.11.02 11:50:05 | 000,035,944 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\symc8xx.sys -- (Symc8xx) DRV - [2006.11.02 11:50:04 | 000,065,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_fc.sys -- (LSI_FC) DRV - [2006.11.02 11:50:03 | 000,034,920 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sym_u3.sys -- (Sym_u3) DRV - [2006.11.02 11:49:59 | 000,033,384 | ---- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\mraid35x.sys -- (Mraid35x) DRV - [2006.11.02 11:49:56 | 000,031,848 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sym_hi.sys -- (Sym_hi) DRV - [2006.11.02 11:49:53 | 000,028,776 | ---- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\megasas.sys -- (megasas) DRV - [2006.11.02 11:49:30 | 000,017,512 | ---- | M] (VIA Technologies, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\viaide.sys -- (viaide) DRV - [2006.11.02 11:49:28 | 000,016,488 | ---- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\cmdide.sys -- (cmdide) DRV - [2006.11.02 11:49:20 | 000,014,952 | ---- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\aliide.sys -- (aliide) DRV - [2006.11.02 10:25:24 | 000,071,808 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brserid.sys -- (Brserid) Brother MFC Serial Port Interface Driver (WDM) DRV - [2006.11.02 10:24:47 | 000,011,904 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brusbser.sys -- (BrUsbSer) DRV - [2006.11.02 10:24:46 | 000,005,248 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brfiltup.sys -- (BrFiltUp) DRV - [2006.11.02 10:24:45 | 000,013,568 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brfiltlo.sys -- (BrFiltLo) DRV - [2006.11.02 10:24:44 | 000,062,336 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brserwdm.sys -- (BrSerWdm) DRV - [2006.11.02 10:24:44 | 000,012,160 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brusbmdm.sys -- (BrUsbMdm) DRV - [2006.11.02 09:36:50 | 000,020,608 | ---- | M] (N-trig Innovative Technologies) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ntrigdigi.sys -- (ntrigdigi) DRV - [2006.11.02 09:30:54 | 000,117,760 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\E1G60I32.sys -- (E1G60) Intel(R) DRV - [2006.09.27 05:01:36 | 000,241,628 | ---- | M] (Syntek America Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\StkAMini.sys -- (StkAMini) DRV - [2006.08.17 16:04:12 | 000,037,120 | ---- | M] (SerComm) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NETGEARUHUB.sys -- (NETGEARUHUB) DRV - [2006.08.17 16:04:04 | 000,011,648 | ---- | M] (SerComm) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NETGEARUCOMP.sys -- (NETGEARUCOMP) DRV - [2006.08.02 08:44:04 | 000,004,772 | ---- | M] (Syntek America Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\StkScan.sys -- (StkScan) DRV - [2006.07.05 14:46:06 | 000,063,352 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\sfdrv01a.sys -- (sfdrv01a) StarForce Protection Environment Driver (version 1.x.a) DRV - [2006.06.14 16:56:56 | 000,013,680 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\sfhlp02.sys -- (sfhlp02) StarForce Protection Helper Driver (version 2.x) DRV - [2006.02.20 20:17:40 | 000,033,408 | ---- | M] (B.H.A Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\cdrbsdrv.sys -- (cdrbsdrv) DRV - [2006.01.26 14:21:04 | 000,034,686 | ---- | M] (Service & Quality Technology.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Capt905c.sys -- (SQTECH905C) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = Google IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/" FF - prefs.js..extensions.enabledItems: fdm_ffext@freedownloadmanager.org:1.3.4 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21 FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\ProgramData\components [2010.07.29 13:40:33 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\ProgramData\plugins [2010.08.05 19:21:14 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Thunderbird 3.0.4\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2010.04.16 18:29:14 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Thunderbird 3.0.4\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2010.04.27 17:32:24 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\mozilla\Extensions [2010.08.05 19:35:43 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\mgpv39s3.default\extensions [2010.08.05 19:25:21 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\mgpv39s3.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} [2008.06.15 18:42:46 | 000,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O2 - BHO: (TBSB04045 Class) - {C6BFC16B-D6FF-47EB-B5D7-F91FB78F94CE} - C:\Program Files\IEToolbar\Amazon Toolbar\amazon.dll () O2 - BHO: (FDMIECookiesBHO Class) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll () O3 - HKLM\..\Toolbar: (Amazon Toolbar) - {EEB30C11-DF11-46DF-B763-BAF798CA65F3} - C:\Program Files\IEToolbar\Amazon Toolbar\amazon.dll () O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (Amazon Toolbar) - {EEB30C11-DF11-46DF-B763-BAF798CA65F3} - C:\Program Files\IEToolbar\Amazon Toolbar\amazon.dll () O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [FreePDF Assistant] C:\Program Files\FreePDF_XP\fpassist.exe (shbox.de) O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation) O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.) O4 - HKLM..\Run: [ Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation) O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe (Nero AG) O4 - HKLM..\Run: [NPSStartup] File not found O4 - HKLM..\Run: [PS121v2] C:\Program Files\NETGEAR\PS121v2\PS121v2.exe () O4 - HKLM..\Run: [RtHDVCpl] File not found O4 - HKLM..\Run: [Skytel] File not found O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) O4 - HKCU..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation) O4 - Startup: C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Registration Heroes of Might & Magic 5.LNK = C:\Program Files\Ubisoft\Heroes of Might and Magic V\registration\RegistrationReminder.exe () O4 - Startup: C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TeamDrive2.lnk = C:\Program Files\TeamDrive2.0\bin\TeamDrive2.exe (TeamDrive Systems GmbH) O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1 O8 - Extra context menu item: Alles mit FDM herunterladen - C:\Program Files\Free Download Manager\dlall.htm () O8 - Extra context menu item: Auswahl mit FDM herunterladen - C:\Program Files\Free Download Manager\dlselected.htm () O8 - Extra context menu item: Datei mit FDM herunterladen - C:\Program Files\Free Download Manager\dllink.htm () O8 - Extra context menu item: Videos mit FDM herunterladen - C:\Program Files\Free Download Manager\dlfvideo.htm () O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O13 - gopher Prefix: missing O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} hxxp://download.bitdefender.com/resources/scanner/sources/de/scan8/oscan8.cab (BDSCANONLINE Control) O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21) O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} Java Plug-in Technology (Java Plug-in 1.4.2) O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab (Shockwave Flash Object) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.103 O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img36.jpg O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img36.jpg O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{0b3c8250-8a1f-11dc-85aa-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{0b3c8250-8a1f-11dc-85aa-806e6f6e6963}\Shell\AutoRun\command - "" = E:\menu.exe -- File not found O33 - MountPoints2\{7fa4c7dc-2e99-11df-8f61-00192148ef11}\Shell - "" = AutoRun O33 - MountPoints2\{7fa4c7dc-2e99-11df-8f61-00192148ef11}\Shell\AutoRun\command - "" = L:\FrameworkCheck.exe -- File not found O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 90 Days ========== [2010.08.08 19:50:32 | 000,000,000 | ---D | C] -- C:\Windows\System32\eu-ES [2010.08.08 19:50:32 | 000,000,000 | ---D | C] -- C:\Windows\System32\ca-ES [2010.08.08 19:50:30 | 000,000,000 | ---D | C] -- C:\Windows\System32\vi-VN [2010.08.08 19:45:33 | 000,000,000 | ---D | C] -- C:\Windows\System32\SPReview [2010.08.08 15:11:05 | 000,000,000 | ---D | C] -- C:\Windows\System32\EventProviders [2010.08.07 17:23:53 | 000,013,824 | ---- | C] (SerComm) -- C:\Windows\System32\drivers\NETGEARUHOST.sys [2010.08.07 17:23:52 | 000,000,000 | ---D | C] -- C:\Program Files\NETGEAR [2010.08.06 20:08:39 | 000,011,648 | ---- | C] (SerComm) -- C:\Windows\System32\NETGEARUCOMP.sys [2010.08.06 20:08:39 | 000,011,648 | ---- | C] (SerComm) -- C:\Windows\System32\drivers\NETGEARUCOMP.sys [2010.08.06 20:04:28 | 000,037,120 | ---- | C] (SerComm) -- C:\Windows\System32\NETGEARUHUB.sys [2010.08.06 20:04:28 | 000,037,120 | ---- | C] (SerComm) -- C:\Windows\System32\drivers\NETGEARUHUB.sys [2010.08.05 19:22:29 | 000,000,000 | ---D | C] -- C:\Windows\Sun [2010.08.05 19:22:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun [2010.08.03 16:49:10 | 000,000,000 | ---D | C] -- C:\rsit [2010.08.03 16:43:23 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro [2010.08.03 16:03:38 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Malwarebytes [2010.08.03 16:03:21 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys [2010.08.03 16:03:20 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys [2010.08.03 16:03:20 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2010.08.03 16:03:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2010.08.01 15:57:16 | 000,000,000 | ---D | C] -- C:\Program Files\ESET [2010.08.01 15:28:50 | 000,000,000 | ---D | C] -- C:\Windows\BDOSCAN8 [2010.07.25 12:51:06 | 000,000,000 | ---D | C] -- C:\ProgramData\updates [2010.07.24 18:20:18 | 000,000,000 | ---D | C] -- C:\ProgramData\NOS [2010.07.24 18:20:18 | 000,000,000 | ---D | C] -- C:\Program Files\NOS [2010.07.08 18:24:42 | 000,000,000 | ---D | C] -- C:\ProgramData\searchplugins [2010.07.08 16:57:33 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\gamigo [2010.07.08 16:56:06 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Martial Empires Luancher OBT [2010.07.08 16:56:06 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\launcher [2010.07.08 16:44:45 | 000,000,000 | ---D | C] -- C:\Gamigo [2010.07.04 12:18:33 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Local\FreePDF_XP [2010.06.25 17:17:34 | 000,718,296 | ---- | C] (Mozilla Foundation) -- C:\ProgramData\mozcpp19.dll [2010.06.25 17:17:34 | 000,014,808 | ---- | C] (Mozilla Corporation) -- C:\ProgramData\plugin-container.exe [2010.06.14 17:43:16 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype [2010.06.13 11:26:36 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe [2010.06.09 20:18:52 | 000,000,000 | ---D | C] -- C:\Program Files\Pegasys Inc [2010.06.06 22:23:42 | 000,000,000 | ---D | C] -- C:\Program Files\NVIDIA Corporation [2010.06.06 17:27:23 | 000,000,000 | ---D | C] -- C:\Program Files\TeamDrive2.5 [2010.05.25 19:17:48 | 000,444,952 | ---- | C] (Creative Labs) -- C:\Windows\System32\wrap_oal.dll [2010.05.25 19:17:48 | 000,109,080 | ---- | C] (Portions (C) Creative Labs Inc. and NVIDIA Corp.) -- C:\Windows\System32\OpenAL32.dll [2010.05.25 19:17:48 | 000,000,000 | ---D | C] -- C:\Program Files\OpenAL [2010.05.25 19:17:06 | 000,000,000 | ---D | C] -- C:\Program Files\Future Games [2010.05.18 20:11:25 | 000,000,000 | -H-D | C] -- C:\Program Files\Temp [2010.05.18 19:57:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Driver Whiz [2010.05.18 19:23:19 | 000,000,000 | ---D | C] -- C:\Program Files\Activision [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files - Modified Within 90 Days ========== [2010.08.10 19:56:00 | 002,883,584 | -HS- | M] () -- C:\Users\***\ntuser.dat [2010.08.10 19:54:59 | 000,000,418 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{7080964A-3D96-4116-B628-6587E344B0DA}.job [2010.08.10 19:54:59 | 000,000,416 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{B6D6128A-3CF1-406B-9062-A041A5B2944C}.job [2010.08.10 19:54:59 | 000,000,416 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{91E93BC7-8B5E-4332-A553-6EF5D16A122C}.job [2010.08.10 18:24:25 | 000,054,784 | ---- | M] () -- C:\Users\***\Desktop\Kassenbuch_2009.xls [2010.08.10 18:13:07 | 000,524,288 | -HS- | M] () -- C:\Users\***\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms [2010.08.10 18:13:07 | 000,065,536 | -HS- | M] () -- C:\Users\***\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf [2010.08.10 18:12:24 | 000,675,174 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2010.08.10 18:12:24 | 000,633,688 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2010.08.10 18:12:24 | 000,146,088 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2010.08.10 18:12:24 | 000,118,694 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2010.08.10 18:12:23 | 001,566,296 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI [2010.08.10 18:07:42 | 000,000,420 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{A85ED906-5250-4E4F-AE1B-4A97B4CABF5C}.job [2010.08.10 18:07:35 | 000,097,333 | ---- | M] () -- C:\ProgramData\nvModes.dat [2010.08.10 18:07:35 | 000,097,333 | ---- | M] () -- C:\ProgramData\nvModes.001 [2010.08.10 18:06:31 | 000,065,536 | ---- | M] () -- C:\Windows\System32\Ikeext.etl [2010.08.10 18:06:24 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2010.08.10 18:06:24 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2010.08.10 18:06:20 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT [2010.08.10 18:06:13 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2010.08.10 18:05:59 | 2146,754,560 | -HS- | M] () -- C:\hiberfil.sys [2010.08.09 22:51:06 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat [2010.08.08 19:56:03 | 000,321,736 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2010.08.08 19:49:11 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf [2010.08.08 19:07:35 | 000,000,749 | RH-- | M] () -- C:\Windows\WindowsShell.Manifest [2010.08.08 18:38:01 | 000,101,888 | ---- | M] (Infineon Technologies AG) -- C:\Windows\System32\ifxcardm.dll [2010.08.08 18:37:41 | 000,082,432 | ---- | M] (Gemalto, Inc.) -- C:\Windows\System32\axaltocm.dll [2010.08.08 18:24:21 | 000,327,680 | ---- | M] () -- C:\Windows\SPInstall.etl [2010.08.07 17:12:22 | 004,682,406 | -H-- | M] () -- C:\Users\***\AppData\Local\IconCache.db [2010.08.06 19:53:26 | 000,088,424 | ---- | M] () -- C:\Users\***\AppData\Local\GDIPFONTCACHEV1.DAT [2010.08.03 16:03:24 | 000,000,855 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2010.08.03 15:46:16 | 000,000,841 | ---- | M] () -- C:\Users\***\Desktop\CCleaner.lnk [2010.07.29 13:40:36 | 000,001,211 | ---- | M] () -- C:\ProgramData\updates.xml [2010.07.29 13:40:36 | 000,000,057 | ---- | M] () -- C:\ProgramData\active-update.xml [2010.07.29 13:40:29 | 000,467,928 | ---- | M] (sqlite.org) -- C:\ProgramData\sqlite3.dll [2010.07.29 13:40:29 | 000,000,701 | ---- | M] () -- C:\ProgramData\updater.ini [2010.07.29 13:40:29 | 000,000,003 | ---- | M] () -- C:\ProgramData\update.locale [2010.07.29 13:40:28 | 000,000,478 | ---- | M] () -- C:\ProgramData\softokn3.chk [2010.07.29 13:40:27 | 000,016,246 | ---- | M] () -- C:\ProgramData\removed-files [2010.07.29 13:40:26 | 000,000,478 | ---- | M] () -- C:\ProgramData\nssdbm3.chk [2010.07.29 13:40:26 | 000,000,141 | ---- | M] () -- C:\ProgramData\platform.ini [2010.07.29 13:40:25 | 001,015,768 | ---- | M] () -- C:\ProgramData\js3250.dll [2010.07.29 13:40:25 | 000,000,478 | ---- | M] () -- C:\ProgramData\freebl3.chk [2010.07.29 13:40:24 | 000,004,296 | ---- | M] () -- C:\ProgramData\crashreporter.ini [2010.07.29 13:40:24 | 000,000,705 | ---- | M] () -- C:\ProgramData\crashreporter-override.ini [2010.07.29 13:40:24 | 000,000,115 | ---- | M] () -- C:\ProgramData\dependentlibs.list [2010.07.29 13:40:21 | 000,031,393 | ---- | M] () -- C:\ProgramData\LICENSE [2010.07.29 13:40:21 | 000,002,530 | ---- | M] () -- C:\ProgramData\blocklist.xml [2010.07.29 13:40:21 | 000,002,126 | ---- | M] () -- C:\ProgramData\application.ini [2010.07.29 13:40:21 | 000,000,220 | ---- | M] () -- C:\ProgramData\browserconfig.properties [2010.07.29 13:40:21 | 000,000,000 | ---- | M] () -- C:\ProgramData\.autoreg [2010.07.08 18:24:43 | 000,001,451 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk [2010.07.07 17:27:31 | 000,000,793 | ---- | M] () -- C:\Users\***\Desktop\Synkron.lnk [2010.06.30 17:11:48 | 000,001,405 | ---- | M] () -- C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Registration Heroes of Might & Magic 5.LNK [2010.06.09 20:19:43 | 000,002,126 | ---- | M] () -- C:\Users\Public\Desktop\TMPGEnc DVD Author 3 with DivX Authoring.lnk [2010.06.06 17:27:52 | 000,001,158 | ---- | M] () -- C:\Users\Public\Desktop\TeamDrive.lnk [2010.05.25 19:17:48 | 000,444,952 | ---- | M] (Creative Labs) -- C:\Windows\System32\wrap_oal.dll [2010.05.25 19:17:48 | 000,109,080 | ---- | M] (Portions (C) Creative Labs Inc. and NVIDIA Corp.) -- C:\Windows\System32\OpenAL32.dll [2010.05.18 19:39:34 | 000,022,328 | ---- | M] () -- C:\Windows\System32\drivers\PnkBstrK.sys [2010.05.18 19:39:34 | 000,022,328 | ---- | M] () -- C:\Users\***\AppData\Roaming\PnkBstrK.sys [2010.05.18 19:39:11 | 000,000,319 | ---- | M] () -- C:\Windows\game.ini [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files Created - No Company Name ========== [2010.08.10 18:16:25 | 000,054,784 | ---- | C] () -- C:\Users\***\Desktop\Kassenbuch_2009.xls [2010.08.08 19:49:11 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf [2010.08.08 19:27:57 | 000,392,170 | ---- | C] () -- C:\Windows\System32\onex.tmf [2010.08.08 19:27:54 | 000,009,212 | ---- | C] () -- C:\Windows\System32\RacUR.xml [2010.08.08 19:27:54 | 000,000,153 | ---- | C] () -- C:\Windows\System32\RacUREx.xml [2010.08.08 19:27:25 | 000,344,698 | ---- | C] () -- C:\Windows\System32\eaphost.tmf [2010.08.08 19:27:22 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll [2010.08.08 19:27:20 | 000,442,788 | ---- | C] () -- C:\Windows\System32\dot3.tmf [2010.08.08 19:26:27 | 011,967,524 | ---- | C] () -- C:\Windows\System32\korwbrkr.lex [2010.08.08 19:26:25 | 003,662,128 | ---- | C] () -- C:\Windows\System32\locale.nls [2010.08.08 19:26:22 | 000,208,966 | ---- | C] () -- C:\Windows\System32\WFP.TMF [2010.08.08 19:26:05 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin [2010.08.08 19:26:05 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin [2010.08.08 19:26:03 | 000,092,918 | ---- | C] () -- C:\Windows\System32\slmgr.vbs [2010.08.08 19:26:02 | 000,009,239 | ---- | C] () -- C:\Windows\System32\spcinstrumentation.man [2010.08.08 19:25:59 | 000,130,008 | ---- | C] () -- C:\Windows\System32\systemsf.ebd [2010.08.08 15:22:42 | 000,000,003 | ---- | C] () -- C:\Windows\System32\drivers\MsftWdf_Kernel_01007_Inbox_Critical.Wdf [2010.08.08 15:20:21 | 000,144,909 | ---- | C] () -- C:\Windows\System32\fsmgmt.msc [2010.08.08 15:20:19 | 000,012,198 | ---- | C] () -- C:\Windows\System32\gatherWiredInfo.vbs [2010.08.08 15:20:07 | 000,195,122 | ---- | C] () -- C:\Windows\System32\winrm.vbs [2010.08.08 15:15:18 | 000,327,680 | ---- | C] () -- C:\Windows\SPInstall.etl [2010.08.06 20:08:39 | 000,001,474 | ---- | C] () -- C:\Windows\System32\NETGEARUCOMP.inf [2010.08.06 20:04:28 | 000,001,434 | ---- | C] () -- C:\Windows\System32\NETGEARUHUB.inf [2010.08.03 16:03:24 | 000,000,855 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2010.07.29 13:40:36 | 000,001,211 | ---- | C] () -- C:\ProgramData\updates.xml [2010.07.29 13:40:36 | 000,000,057 | ---- | C] () -- C:\ProgramData\active-update.xml [2010.07.29 13:40:24 | 000,000,115 | ---- | C] () -- C:\ProgramData\dependentlibs.list [2010.07.07 17:27:31 | 000,000,793 | ---- | C] () -- C:\Users\***\Desktop\Synkron.lnk [2010.06.30 17:11:48 | 000,001,405 | ---- | C] () -- C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Registration Heroes of Might & Magic 5.LNK [2010.06.27 10:46:45 | 000,057,667 | ---- | C] () -- C:\Windows\System32\ieuinit.inf [2010.06.09 20:19:43 | 000,002,126 | ---- | C] () -- C:\Users\Public\Desktop\TMPGEnc DVD Author 3 with DivX Authoring.lnk [2010.06.07 10:55:50 | 000,097,333 | ---- | C] () -- C:\ProgramData\nvModes.001 [2010.06.07 10:55:49 | 000,097,333 | ---- | C] () -- C:\ProgramData\nvModes.dat [2010.06.06 17:27:52 | 000,001,158 | ---- | C] () -- C:\Users\Public\Desktop\TeamDrive.lnk [2010.05.18 19:39:34 | 000,022,328 | ---- | C] () -- C:\Users\***\AppData\Roaming\PnkBstrK.sys [2010.05.18 19:39:11 | 000,000,319 | ---- | C] () -- C:\Windows\game.ini [2010.03.13 14:08:30 | 000,691,696 | ---- | C] () -- C:\Windows\System32\drivers\sptd.sys [2010.01.06 19:36:39 | 000,116,224 | ---- | C] () -- C:\Windows\System32\redmonnt.dll [2009.12.15 21:15:46 | 000,110,592 | ---- | C] () -- C:\Windows\System32\FsUsbExDevice.Dll [2009.12.15 21:15:46 | 000,036,608 | ---- | C] () -- C:\Windows\System32\FsUsbExDisk.Sys [2009.12.15 19:51:14 | 000,005,632 | ---- | C] () -- C:\Windows\System32\drivers\StarOpen.sys [2009.12.03 09:27:28 | 000,080,416 | ---- | C] () -- C:\Windows\System32\RtNicProp32.dll [2009.08.29 22:04:01 | 000,120,200 | ---- | C] () -- C:\Windows\System32\DLLDEV32i.dll [2009.08.29 22:03:10 | 000,005,937 | ---- | C] () -- C:\Windows\mgxoschk.ini [2009.08.04 21:43:38 | 000,278,728 | ---- | C] () -- C:\Windows\System32\drivers\atksgt.sys [2009.08.04 21:43:37 | 000,025,416 | ---- | C] () -- C:\Windows\System32\drivers\lirsgt.sys [2009.08.03 01:21:54 | 000,197,912 | ---- | C] () -- C:\Windows\System32\physxcudart_20.dll [2009.08.03 01:21:54 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelTraditionalChinese.dll [2009.08.03 01:21:54 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSwedish.dll [2009.08.03 01:21:54 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSpanish.dll [2009.08.03 01:21:54 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSimplifiedChinese.dll [2009.08.03 01:21:54 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelPortugese.dll [2009.08.03 01:21:54 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelKorean.dll [2009.08.03 01:21:54 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelJapanese.dll [2009.08.03 01:21:52 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelGerman.dll [2009.08.03 01:21:52 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelFrench.dll [2009.03.02 11:33:32 | 000,067,584 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll [2009.03.02 11:33:32 | 000,000,547 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll.manifest [2009.01.05 14:44:10 | 000,000,483 | ---- | C] () -- C:\Windows\bdoscandellang.ini [2008.09.01 22:16:37 | 000,002,793 | ---- | C] () -- C:\Windows\RBuilder.ini [2008.07.19 12:39:33 | 000,022,328 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys [2008.06.15 18:50:38 | 000,000,049 | ---- | C] () -- C:\Windows\NeroDigital.ini [2008.05.04 18:39:34 | 000,002,560 | ---- | C] () -- C:\Windows\System32\ViaClassCoInstaller.dll [2007.12.31 14:58:03 | 000,159,744 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll [2007.12.31 14:58:02 | 000,552,960 | ---- | C] () -- C:\Windows\System32\xvidcore.dll [2007.11.17 13:42:56 | 000,000,097 | ---- | C] () -- C:\Windows\System32\PICSDK.ini [2006.11.02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll [2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini [2006.08.11 09:52:02 | 000,012,288 | ---- | C] () -- C:\Windows\System32\EvOnlDiag.dll ========== LOP Check ========== [2008.07.13 16:28:54 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\AD ON Multimedia [2010.03.13 14:23:31 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\DAEMON Tools Lite [2010.01.22 18:30:06 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Desktopicon [2008.12.01 23:41:55 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\EleFun Desktops [2009.12.29 11:45:46 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Free Download Manager [2010.07.08 17:20:16 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\gamigo [2009.12.16 18:09:44 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Itsth [2010.07.08 16:56:12 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\launcher [2009.08.29 22:04:42 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\MAGIX [2010.07.08 16:56:12 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Martial Empires Luancher OBT [2009.12.16 18:30:09 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Matus Tomlein [2009.12.21 15:27:50 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Nokia [2009.12.21 17:12:15 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\PC Suite [2009.06.08 21:21:18 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\phonostar-Player [2009.12.15 21:15:22 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Samsung [2010.07.05 20:48:49 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\TeamDrive [2008.06.15 18:42:46 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Toolbars [2009.12.31 00:12:14 | 000,000,000 | ---D | M] -- C:\Users\***\AppData\Roaming\Xilisoft [2010.08.09 22:51:08 | 000,032,546 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT [2010.08.10 19:54:59 | 000,000,418 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{7080964A-3D96-4116-B628-6587E344B0DA}.job [2010.08.10 19:54:59 | 000,000,416 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{91E93BC7-8B5E-4332-A553-6EF5D16A122C}.job [2010.08.10 18:07:42 | 000,000,420 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{A85ED906-5250-4E4F-AE1B-4A97B4CABF5C}.job [2010.08.10 19:54:59 | 000,000,416 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{B6D6128A-3CF1-406B-9062-A041A5B2944C}.job ========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:4FF9FD44 < End of report > |
10.08.2010, 19:27 | #18 |
/// Selecta Jahrusso | pc sauber nach flacor.dat? Noch Probleme ?
__________________
__________________ |
10.08.2010, 21:30 | #19 |
| pc sauber nach flacor.dat? Nö! Keine Probleme in letzter Zeit ! |
10.08.2010, 23:00 | #20 |
/// Selecta Jahrusso | pc sauber nach flacor.dat? Logfile ist sauber Hier noch die letzten paar Schritte zur Säuberung Deines Rechners. Schritt 1 Systemwiederherstellungpunkte leeren Windows +E Taste drücken --> Rechtsklick über Laufwerk C --> Eigenschaften --> Bereinigen --> weitere Optionen --> Systemwiederherstellung und Schattenkopien bereinigen. Schritt 2 Tool CleanUp Starte bitte die OTL.exe. Klicke nun auf den Bereinigung Button. Dies wird die meisten Tools und Logfiles entfernen. Sollte denoch etwas bestehen bleiben, bitte manuell entfernen sowie den Papierkorb leeren. Schritt 3 Automatische Updates Sehen wir nach ob die Updates für Windows sich automatisch downloaden. Das ist der beste Weg um all die Sicherheits- Patches und Fixes zu erhalten. Windows + R Taste drücken. Kopiere nun folgenden Text in die Kommandozeile RunDll32.exe shell32.dll,Control_RunDLL wscui.cpl und klicke auf OK. Stelle sicher das die automatischen Updates aktiviert sind. Schritt 4 Um Dich für die Zukunft vor weiteren Infizierungen zu schützen empfehle ich Dir noch ein paar Programme.
Schritt 5 Tipps für sicheres Surfen Das sind meine Vorschläge. Verwende einen alternativen Browser statt den IE. Ich empfehle Mozilla Firefox. Für Firefox gibt es verschiedenste AddOns um sicher durch das WWW zu kommen.
Don'ts
Nun bleibt mir nur noch dir viel Spass beim sicheren Surfen zu wünschen. Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ mfg, Daniel ASAP & UNITE Member Alliance of Security Analysis Professionals Unified Network of Instructors and Trusted Eliminators Lerne, zurück zu schlagen und unterstütze uns! TB Akademie |
14.08.2010, 18:55 | #21 |
| pc sauber nach flacor.dat? Ok, vielen Dank und Ein dreifach Daumenhoch für eure Hilfe. |
14.08.2010, 23:55 | #22 |
/// Selecta Jahrusso | pc sauber nach flacor.dat? Froh das wir helfen konten Dieses Thema scheint erledigt und wird aus meinen Abos gelöscht. Solltest Du das Thema erneut brauchen schicke mir bitte eine PM. Jeder andere möge bitte einen eigenen Thread erstellen
__________________ mfg, Daniel ASAP & UNITE Member Alliance of Security Analysis Professionals Unified Network of Instructors and Trusted Eliminators Lerne, zurück zu schlagen und unterstütze uns! TB Akademie |
Themen zu pc sauber nach flacor.dat? |
abonnement, antivir, antivir guard, avgntflt.sys, bho, browser, c:\windows\system32\rundll32.exe, desktop, excel, fehler, firefox, flacor.dat, flash player, hdaudio.sys, hijack, hijackthis, home premium, hotfix.exe, iastor.sys, installation, locker, logfile, msiexec, msiexec.exe, mssql, notepad.exe, nvlddmkm.sys, object, office 2007, programdata, realtek, registry, rundll, senden, server, services.exe, software, sptd.sys, staropen, start menu, svchost.exe, system, trustedinstaller, uleadburninghelper, usb, virus, vlc media player, windows-sicherheitscenterdienst, wscript.exe |